Skip to content

Report a security issue

How to report a vulnerability privately, what to include, what not to include, and what we do with it.

2 min read · Updated August 22, 2026

How to report

Use the security topic. Security reports are read first, ahead of everything else in the queue.

What to include

  1. What you found, in one sentence.
  2. The exact steps to reproduce it.
  3. What an attacker could do with it.
  4. Any affected URL.

What not to include

Do not paste working exploit payloads into the form. Describe the mechanism and we will reproduce it. Do not include real user data, credentials, session tokens or private keys, including your own.

What we ask of you

Please do not run automated scans against the site, do not attempt to access another person's data, and do not degrade the service to demonstrate that you can. Report it and we will take it seriously without the demonstration.

What happens next

We acknowledge the report, reproduce it, and tell you what we found. If it is real we fix it and tell you when. We do not currently run a paid bounty program, and we will say so rather than let you assume otherwise.

Did this answer it?

If not, say so. Describe what you were trying to do and what happened instead, and the answer usually becomes a better version of this article.